Skip to content
Contact us

Application penetration testing since 2010

We test the whole surface,
including the edge nobody drew.

Every application is a map of trust boundaries — clients, gateways, identity, data. We test all of them, including the edge that never made it onto anyone's diagram.

attack surface· one application, mappedhover a boundary
browserweb clientmobileiOS / Androidpartnerserver-to-serverapi gatewayauthn + rate limitidentityroles / scopestenant dataper-customer recordsobject storedocumentsexport serviceno ownership re-checkCWE-639

← drag to follow the path →

Hover or tap any boundary to see what we test there.

Who we are

Engineers who attack software

We are software engineers who specialise in attacking software. That background is why we find the flaws that require understanding a system rather than recognising a pattern — broken authorization, business logic abused exactly as designed, one tenant reaching another tenant’s data.

Web applications, REST APIs, mobile and AI-enabled systems, tested by engineers who build their own platform, CybeRapid, to take the repetitive work out of an engagement so more of our time goes on the parts that need judgement.

Founded in 2010 by Erez Metula, author of Managed Code Rootkits. Application security is the only thing we do.

  • Specialists, not generalistsApplication security only — no network audits, no compliance box-ticking as a side business.
  • The same people throughoutYou are not handed to a junior after the kick-off call.
  • Tools as acceleratorsAutomation and AI take the repetitive work; judgement stays human.
  • Retesting includedA finding is not closed until it has been verified as fixed.

Trusted by security teams at

CyberArkTevaNICECoca-ColaPayoneerFireblocksMedtroniceToroBigIDNCRToyotaAXACTERAironSourceCyberArkTevaNICECoca-ColaPayoneerFireblocksMedtroniceToroBigIDNCRToyotaAXACTERAironSource

The process

How an engagement runs

Six steps from first call to verified fix. You always know where the engagement is, what has been found so far and what happens next — there is no silent period where we disappear and return with a PDF.

1

Scoping

We learn what the system does.

2

Testing

Hands-on testing against the catalogue.

3

Report

Written for whoever has to fix it.

4

Walkthrough

A session with your developers.

5

Repair

Your team fixes; we stay available.

6

Retest

Every finding verified. Included.

01

Scoping

A remote session in which we go through the application with you: what it does, who its users are, which roles exist and what would hurt most if it went wrong. We agree the scope, the environment and the timeline before anything starts, so you get a fixed plan rather than an open-ended engagement. If a penetration test is not what you need yet, this is where we say so.

02

Testing

We work through the application as an attacker would, authenticated as each role, following the workflows and the business logic to their edges. Testing is driven by our published catalogue so coverage is deliberate rather than improvised. Anything critical reaches you the same day we find it — you never wait for the report to learn something urgent.

03

Report

Every finding states what it is, how to reproduce it step by step, what an attacker actually achieves with it in your application, and a concrete remediation. Severity reflects real impact rather than a generic score: an issue that exposes another customer’s data is treated as what it is.

04

Walkthrough

We sit with the development team and go through the findings one by one — what we did, why it works, and what a correct fix looks like. It is the fastest way to turn a report into fixes, and the point where most questions get answered before anyone writes code.

05

Repair

Your developers implement the remediations. We remain reachable while that happens: reviewing a proposed fix, confirming an approach, or clarifying a finding costs a message rather than a change request.

06

Retest

We retest every reported finding against the fixed build and confirm each one is genuinely closed. This is part of the engagement, not an upsell — and it is regularly where a team discovers that a fix addressed the symptom rather than the cause.

The deliverable

A report your developers can act on

Testing is only useful if someone can act on it. Our reports are written for the engineers who have to fix the problem — reproduction steps, real impact, and a concrete remediation.

The findings that need context

Authorization flaws, tenant isolation failures, workflow abuse and chained issues do not look malformed to a tool. Finding them takes someone who understands what your application is supposed to allow before they can say what it should not.

Human-led, accelerated by our own platform

Automation finds the known patterns. People find the flaws that only make sense once you understand what the application is supposed to do — and that is where the serious findings live.

Built to remove the repetitive work

We built CybeRapid to take the mechanical part of an engagement off our testers, so more of their time goes on the parts that need judgement — and so the report you get is deeper for the same number of days.

In their words

What clients say

Every quote comes from a real engagement. These are anonymised because our agreement with those clients requires it — not because there is anything vague about the work.

They found a critical IDOR in our claims portal within the first two days. We had been live for 18 months without anyone catching it.
VP EngineeringDigital insurance platform
Their API security assessment covered edge cases we hadn’t thought of — broken object-level authorization, mass assignment, rate limiting gaps. The report read like a masterclass in API security.
Backend Team LeadDeveloper tools platform
We needed SOC 2 compliance fast. AppSec Labs didn’t just run the pentest — they helped us understand which findings were blockers and which could wait, so we passed the audit on our first attempt.
Head of OperationsB2B SaaS startup

Read all of them

AppSec Labs on the Microsoft Azure Marketplace

Another way to buy

Available on the Microsoft Azure Marketplace

Our web application penetration testing is listed on the Azure Marketplace, so if your organisation already buys through Azure you can procure a test there and draw it down against your existing Microsoft commitment.

It is simply an additional route. Most clients engage us directly, and scoping, testing and reporting are identical either way — pick whichever is easier for your procurement.

View the Azure Marketplace listing

Evidence

We publish the tests themselves

Most firms describe their methodology in a paragraph. Ours is 276 named test cases across 42 category pages — each stating what the test proves, how it is carried out, what has to be in place beforehand and what a positive result looks like. Every identifier is checked against the standard it belongs to before it is published: 981 verified control references across WSTG, ASVS, MASVS, the OWASP LLM Top 10 and CWE.

  • 276Named test cases
  • 42Category pages
  • 981Verified control refs
  • 5Standards mapped
  • 107Web and API
  • 26AI and LLM
  • 106Android and iOS
  • 37IoT and embedded

See all 276 test casesCoverage matrix

Questions

Frequently asked

What exactly is an application penetration test?

A hands-on security assessment where experienced testers attack your application the way a real attacker would — looking for ways to reach data or functionality they should not be able to reach.

What do we actually receive at the end?

A report written for the people who have to fix the problem. Every finding includes what it is, how to reproduce it step by step, the real business impact, and a concrete remediation.

Do you use automated tools or AI?

Both, as accelerators — never as a substitute for a human. We use our own platform, CybeRapid, to take the repetitive work out of an engagement so that more of our testers' time goes on the parts that need judgement.

How long does a test take?

It depends on the size of the application and the number of roles and workflows involved, but a typical engagement runs from a few days to a few weeks. We scope it with you first so you get a fixed timeline.

Do you retest after we fix the issues?

Yes. A finding is not closed until it has been verified as fixed, and retesting is part of the engagement rather than an upsell. It is also the point at which many teams discover a fix was incomplete.

Can you help with compliance requirements?

Yes — our testing and reporting are regularly used to satisfy customer security reviews, regulatory expectations and certification requirements.

All questions

Get in touch

Tell us what the system does and what worries you.

We will come back with scoping questions, a clear proposal and a realistic timeline. If a penetration test is not what you need yet, we will say so.

  • No obligationScoping costs you a conversation, not a commitment.
  • Under NDA as standardHappy to sign yours rather than insist on ours.
  • A person, not a queueYou speak to someone who will be on the engagement.

Read what clients say